
blackarch
An ArchLinux based distribution for penetration testers and security researchers.

An ArchLinux based distribution for penetration testers and security researchers.

Compiles EAC and EOC anti-cheat SDKs, reversing research, and code resources to study how game anti-cheat systems integrate and operate.

Research notes documenting CVE-2024-30350, an out-of-bounds read in Foxit PDF Reader annotation handling, covering triage, disclosure, and defensive…

Curated guide to becoming a malware analyst, covering essential knowledge, reverse engineering, analysis tools, and LLM-assisted learning with…

Agent skills for firmware extraction, static analysis, Ghidra reverse engineering, emulation, and security reporting, packaged for Claude Code and…

Technical analysis of the XZ Utils backdoor (CVE-2024-3094), explaining the supply chain attack, obfuscation techniques, and impact on OpenSSH via…

A book-in-progress about the Linux kernel and its insides.

Security-research lab: controlled reproduction of CVE-2026-33075 (pwn request in labring/FastGPT preview-image workflow, pull_request_target +…

Collection of Solidity snippets and Foundry scripts for smart contract security audits

Technical whitepaper dissecting JioPC cloud VDI architecture, including hardware specs, session termination mechanisms, and security limitations,…

Curated OSINT compilation on Log4Shell (CVE-2021-44228) covering detection methods, attack surface, mitigation steps, and indicators of compromise…

AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0,…

Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details…

Research and detection toolkit for Linux kernel LPE CVE-2026-31431, including exploit analysis, YARA rules, auditd/Falco detection, patching guide,…

A scanner and testter of the CVE-2025-11001 of 7-zip

Technical analysis and educational documentation of CVE-2026-7482, a critical heap buffer over-read in Ollama's GGUF loader, including exploitation…

Detailed analysis of CVE-2021-22569, a high-severity denial-of-service vulnerability in protobuf-java, including affected versions, patched versions,…

Benchmark task for reimplementing a masked path-resolution fix in Jupyter Server, with functional and hidden security tests to evaluate…